"New Phishing Toolkit Uses PWAs to Steal Login Credentials"

With a new phishing kit, red teams and cybercriminals can create Progressive Web Apps (PWAs) with convincing corporate login forms aimed at stealing credentials. A PWA is a web-based app built with HTML, CSS, and JavaScript that can be installed from a website like a desktop application. Mr.d0x, a security researcher, has developed a new phishing toolkit that demonstrates how to create PWAs to display corporate login forms, including a fake address bar that shows the normal corporate login URL. This article continues to discuss the new phishing toolkit involving PWAs.

Bleeping Computer reports "New Phishing Toolkit Uses PWAs to Steal Login Credentials"

Submitted by grigby1

Submitted by grigby1 CPVI on